@stanleytan
Update regarding the recent SAND bridge incident.
As shared this past Saturday, the exploit was rapidly contained. Since then, our team has completed the on-chain forensic investigation in collaboration with external security partners.
Root cause: on Base and BNB Chain, the SAND token contract also acts as the LayerZero bridge integration. The attacker used a configuration function on that contract to register themselves as the sole verifier of incoming bridge messages, which allowed them to mint unbacked SAND on both networks. The SAND contract was audited by a third party prior to deployment, and we’re investigating why this vulnerability wasn’t identified in the audit.